Logo
vulnerabilityCVE-2025-7039
Name
CVE-2025-7039
Source
NVD ( link)Debian ( link)
Description
A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temporary file content by creating symbolic links. This vulnerability allows a local attacker to manipulate file paths and access unauthorized data. The core issue stems from insufficient validation of file path lengths during temporary file operations.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Vulnerability Ratings#


3.7
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
2.86.5
Not Affected
buildroot
master
2.86.5
Not Affected
openwrt
master
2.88.1-r1
Not Affected
openwrt
openwrt-25.12
2.82.0-r1
Not Affected

Resolved with patches#


libglib2 (buildroot:2025.02.x)

#
Title
Author
Resolve
1
gfileutils: fix computation of temporary file name
Michael Catanzaro <mcatanzaro@redhat.com>
CVE-2025-7039